Wednesday, March 4, 2015

9 Facts About Computer Security That Experts Wish You Knew


9 Facts About Computer Security That Experts Wish You Knew

Every day, you hear about security flaws, viruses, and evil hacker gangs that could leave you destitute — or, worse, bring your country to its knees. But what's the truth about these digital dangers? We asked computer security experts to separate the myths from the facts. Here's what they said.

1. Having a strong password actually can prevent most attacks

Yahoo's Chief Information Security Officer Alex Stamos has spent most of his career finding security vulnerabilities and figuring out how attackers might try to exploit software flaws. He's seen everything from the most devious hacks to the simplest social engineering scams. And in all that time, he's found that there are two simple solutions for the vast majority of users: strong passwords and two-factor authentication.
Stamos says that the biggest problem is that the media focuses on stories about the deepest and most complicated hacks, leaving users feeling like there's nothing they can do to defend themselves. But that's just not true. He told me via email:
I've noticed a lot of nihilism in the media, security industry and general public since the Snowden docs came out. This generally expresses itself as people throwing up their hands and saying "there is nothing we can do to be safe". While it's true that there is little most people can do when facing a top-tier intelligence apparatus with the ability to rewrite hard drive firmware, this should not dissuade users from doing what they can to protect themselves from more likely threats and security professionals from building usable protections for realistic adversaries.
Users can protect themselves against the most likely and pernicious threat actors by taking two simple steps:
1) Installing a password manager and using it to create unique passwords for every service they use.
2) Activating second-factor authentication options (usually via text messages) on their email and social networking accounts.
The latter is especially important since attackers love to take over the email and social accounts of millions of people and then automatically use them to pivot to other accounts or to gather data on which accounts belong to high-value targets.
So I would really like the media to stop spreading the idea that just because incredible feats are possible on the high-end of the threat spectrum that it isn't possible to keep yourself safe in the vast majority of scenarios.
Adam J. O'Donnell, a Principal Engineer with Cisco's Advanced Malware Protection group, amplified Stamos' basic advice:
Oh, and my advice for the average person: Make good backups and test them. Use a password vault and a different password on every website.
Yep, having a good password is easy — and it's still the best thing you can do.

2. Just because a device is new does not mean it's safe

When you unwrap the box on your new phone, tablet or laptop, it smells like fresh plastic and the batteries work like a dream. But that doesn't mean your computer isn't already infected with malware and riddled with security vulnerabilities.
I heard this from many of the security experts I interviewed. Eleanor Saitta is the technical director for the International Modern Media Institute, and has worked for over a decade advising governments and corporations about computer security issues. She believes that one of the most pernicious myths about security is that devices begin their lives completely safe, but become less secure as time goes on. That's simply not true, especially when so many devices come with vulnerable adware like Superfish pre-installed on them (if you recall, Superfish came pre-installed on many Lenovo laptop models):
That's why the Superfish thing was such a big deal. They built a backdoor in, and they built a really bad, incompetent one, and now it turns out that anybody can walk through.
When you're relying on code delivered by somebody else, a service online or box that you don't control, chances are good that it's not acting in your interest, because it's trying to sell you. There's a good chance that it's already owned or compromised by other people. We don't have a good way of dealing with trust and managing it right now. And all sorts of people will be using that code.
The other issue, which erupted in the media over the past day with the FREAK attack, is that many machines come pre-installed with backdoors. These are baked in by government request, to make it easier for law enforcement and intelligence agencies to track adversaries. But unfortunately, backdoors are also security vulnerabilities that anyone can take advantage of. Says Saitta:
I think one thing that is really important to understand is that if you built a monitoring system into a network like a cell network, or into a crypto system, anybody can get in there. You've built a vulnerability into the system, and sure, you can control access a little. But at the end of the day, a backdoor is a backdoor, and anybody can walk through it.

3. Even the very best software has security vulnerabilities

Many of us imagine that sufficiently good software and networks can be completely safe. Because of this attitude, many users get angry when the machines or services they use turn out to be vulnerable to attack. After all, if we can design a safe car, why not a safe phone? Isn't it just a matter of getting the tech and science right?
But Parisa Tabriz told me via email that you can't look at information security that way. Tabriz is the engineer who heads Google's Chrome security team, and she believes that information security is more like medicine — a bit of art and science — rather than pure science. That's because our technology was built by humans, and is being exploited by humans with very unscientific motivations. She writes:
I think information security is a lot like medicine — it's both an art and science. Maybe this is because humans have explicitly built technology and the internet. We assume we should be able to built them perfectly, but the complexity of what we've built and now hope to secure almost seems impossible. Securing it would require us to have zero bugs, and that means that the economics are not on the side of the defenders. The defenders have to make sure there are zero bugs in all software they use or write (typically many millions of lines of code if you consider the operating system too), whereas the attacker only has to find one bug.
There will always be bugs in software. Some subset of those bugs will have security impact. The challenge is figuring out which ones to spend resources on fixing, and a lot of that is based on presumed threat models that probably would benefit from more insight into people's motivations, like crime, monitoring, etc.
RAND Corporation computer security researcher Lillian Ablon emailed me to say that there is simply no such thing as a completely secure system. The goal for defenders is to make attacks expensive, rather than impossible:
With enough resources, there is always a way for an attacker to get in. You may be familiar with the phrase "it's a matter of when, not if," in relation to a company getting hacked/breached. Instead, the goal of computer security is to make it expensive for the attackers (in money, time, resources, research, etc.).

4. Every website and app should use HTTPS

You've heard every rumor there is to hear about HTTPS. It's slow. It's only for websites that need to be ultra-secure. It doesn't really work. All wrong. The Electronic Frontier Foundation's Peter Eckersley is a technologist who has been researching the use of HTTPS for several years, and working on the EFF's HTTPS Everywhere project. He says that there's a dangerous misconception that many websites and apps don't need HTTPS. He emailed to expand on that:
Another serious misconception is website operators, such as newspapers or advertising networks, thinking "because we don't process credit card payments, our site doesn't need to be HTTPS, or our app doesn't need to use HTTPS". All sites on the Web need to be HTTPS, because without HTTPS it's easy for hackers, eavesdroppers, or government surveillance programs to see exactly what people are reading on your site; what data your app is processing; or even to modify or alter that data in malicious ways.
Eckersley has no corporate affiliations (EFF is a nonprofit), and thus no potential conflict of interest when it comes to promoting HTTPS. He's just interested in user safety.

5. The cloud is not safe — it just creates new security problems

Everything is cloud these days. You keep your email there, along with your photos, your IMs, your medical records, your bank documents, and even your sex life. And it's actually safer there than you might think. But it creates new security problems you might not have thought about. Security engineer Leigh Honeywell works for a large cloud computing company, and emailed me to explain how the cloud really works. She suggests that you begin thinking about it using a familiar physical metaphor:
Your house is your house, and you know exactly what the security precautions you've taken against intruders are - and what the tradeoffs are. Do you have a deadbolt? An alarm system? Are there bars on the windows, or did you decide against those because they would interfere with your decor?
Or do you live in an apartment building where some of those things are managed for you? Maybe there's a front desk security person, or a key-card access per floor. I once lived in a building where you had to use your card to access individual floors on the elevator! It was pretty annoying, but it was definitely more secure. The security guard will get to know the movement patterns of the residents, will potentially (though not always, of course!) recognize intruders. They have more data than any individual homeowner.
Putting your data in the cloud is sort of like living in that secure apartment building. Except weirder. Honeywell continued:
Cloud services are able to correlate data across their customers, not just look at the ways an individual is being targeted. You may not [control access to the place where] your data is being stored, but there's someone at the front desk of that building 24/7, and they're watching the logs and usage patterns as well. It's a bit like herd immunity. A lot of stuff jumps out at [a defender] immediately: here's a single IP address logging into a bunch of different accounts, in a completely different country than any of those accounts have been logged into from ever before. Oh, and each of those accounts received a particular file yesterday — maybe that file was malicious, and all of those accounts just got broken into?
But if it's a more targeted attack, the signs will be more subtle. When you're trying to defend a cloud system, you're looking for needles in haystacks, because you just have so much data to handle. There's lots of hype about "big data" and machine learning right now, but we're just starting to scratch the surface of finding attackers' subtle footprints. A skilled attacker will know how to move quietly and not set off the pattern detection systems you put in place.
In other words, some automated attack methods become blatantly obvious in a cloud system. But it also becomes easier to hide. Honeywell says that users need to consider the threats they're seriously worried about when choosing between a cloud service and a home server:
Cloud services are much more complex systems than, say, a hard drive plugged into your computer, or an email server running in your closet. There are more places that things can go wrong, more moving parts. But there are more people maintaining them too. The question folks should ask themselves is: would I be doing a better job running this myself, or letting someone with more time, money, and expertise do it? Who do you think of when you think about being hacked — is it the NSA, random gamer assholes, an abusive ex-partner? I ran my own email server for many years, and eventually switched to a hosted service. I know folks who work on Gmail and Outlook.com and they do a vastly better job at running email servers than I ever did. There's also the time tradeoff — running an email server is miserable work! But for some people it's worth it, though, because NSA surveillance really is something they have worry about.

6. Software updates are crucial for your protection

There are few things more annoying in life than the little pop-up that reminds you that updates are required. Often you have to plug your device in, and the updates can take a really long time. But they are often the only thing that stands between you and being owned up by a bad guy. Cisco's O'Donnell said:
Those software update messages are [not] there just to annoy you: The frequency of software updates is driven less by new software features and more because of some very obscure software flaw that an attacker can exploit to gain control of your system. These software patches fix issues that were publicly identified and likely used in attacks in the wild. You wouldn't go for days without cleaning and bandaging a festering wound on your arm, would you? Don't do that to your computer.

7. Hackers are not criminals

Despite decades of evidence to the contrary, most people think of hackers as the evil adversaries who want nothing more than to steal their digital goods. But hackers can wear white hats as well as black ones — and the white hats break into systems in order to get there before the bad guys do. Once the vulnerabilities have been identified by hackers, they can be patched. Google Chrome's Tabriz says simply:
Also, hackers are not criminals. Just because someone knows how to break something, doesn't mean they will use that knowledge to hurt people. A lot of hackers make things more secure.
O'Donnell emphasizes that we need hackers because software alone can't protect you. Yes, antivirus programs are a good start. But in the end you need security experts like hackers to defend against adversaries who are, after all, human beings:
Security is less about building walls and more about enabling security guards. Defensive tools alone can't stop a dedicated, well resourced attacker. If someone wants in bad enough, they will buy every security tool the target may have and test their attacks against their simulated version of the target's network. Combatting this requires not just good tools but good people who know how to use the tools.
RAND's Ablon adds that malicious hackers are rarely the threat they are cracked up to be. Instead, the threat may come from people you don't suspect — and their motivations may be far more complicated than mere theft:
A lot of the time an internal employee or insider is just as big of a threat, and could bring a business to its knees – intentionally or inadvertently. Furthermore, there are distinct types of external cyber threat actors (cybercriminals, state-sponsored, hacktivists) with different motivations and capabilities. For example, the cybercriminals who hacked into Target and Anthem had very different motivations, capabilities, etc. than those of the state-sponsored actors who hacked into Sony Pictures Entertainment.

8. Cyberattacks and cyberterrorism are exceedingly rare

As many of the experts I talked to said, your biggest threat is somebody breaking into your accounts because you have a crappy password. But that doesn't stop people from freaking out with fear over "cyberattacks" that are deadly. Ablon says that these kinds of attacks are incredibly unlikely:
Yes, there are ways to hack into a vehicle from anywhere in the world; yes, life-critical medical devices like pacemakers and insulin pumps often have IP addresses or are enabled with Bluetooth – but often these types of attacks require close access, and exploits that are fairly sophisticated requiring time to develop and implement. That said, we shouldn't be ignoring the millions of connected devices (Internet of Things) that increase our attack surface.
Basically, many people fear cyberattacks for the same reason they fear serial killers. They are the scariest possible threat. But they are also the least likely.
As for cyberterrorism, Ablon writes simply, "Cyberterrorism (to date) does not exist ... what is attributed to cyberterrorism today, is more akin to hacktivism, e.g., gaining access to CENTCOM's Twitter feed and posting ISIS propaganda."

9. Darknet and Deepweb are not the same thing

Ablon writes that one of the main problems she has with media coverage of cybercrime is the misuse of the terms "Darknet" and "Deepweb."
She explains what the terms really mean:
The Deepweb refers to part of the Internet, specifically the world wide web (so anything that starts www) that isn't indexed by search engines (so can't be accessed by Google). The Darknet refers to non-"www" networks, where users may need separate software to access them. For example, Silk Road and many illicit markets are hosted on [Deepweb] networks like I2P and Tor.
So get a password vault, use two-factor auth, visit only sites that use HTTPS, and stop worrying about super intricate cyber attacks from the Darknet. And remember, hackers are here to protect you — most of the time, anyway.

Monday, February 10, 2014

Cybersecurity in slow lane one year after Obama order

Cybersecurity in slow lane one year after Obama order
Nearly a year after President Barack Obama issued an executive order to improve the cybersecurity of the nation’s vital assets, the administration doesn’t have much to show: The government is about to produce only some basic standards, with little incentive for the private sector to participate..........

Monday, April 1, 2013

World's biggest DDOS that almost broke the Internet

Last week the largest distributed denial-of-service (DDOS) attack ever occurred. A massive 300Gbps DDOS attack was thrown against Internet blacklist maintainer Spamhaus' website. Click to read more....
World's biggest DDOS attack that almost broke the Internet

Thursday, February 21, 2013

This is How China Hacks America: Inside the Mandiant Report

An unusually detailed 60-page study, just released by Mandiant, an American computer security firm, tracks for the first time individual members of the most sophisticated of the Chinese hacking groups — known to many of its victims in the United States as “Comment Crew” or “Shanghai Group” — to the doorstep of the military unit’s headquarters.

Get it here: Mandiant APT Report

Mandiant has also released an automated assessment tool that can tell if you've been infected. Contact IDP for more information.

Monday, February 11, 2013

America's embarrassingly redundant and entangled cyber security complex

Thank goodness no serious observer of electronic warfare considers a cyber-9/11 possible, let alone imminent
 

The cyber security capabilities of the United States have come under scrutiny in light of recent high-profile Chinese penetrations of American corporate networks. In many ways, cyber has become the handwavium of warfare — step two in a three-step process, sandwiched between "Meet the enemy in battle" and "Victory!"

Before the relatively new interest in cyber security, the fastest way for public agencies to increase their share of a budget was to build a special operations capability. That's why such noted demilitarized zones as Bloomington, Minn., have their own special operations forces, and every Mayberry police department in post-9/11 America wants federal funds to buy drones, periscopes, and assault rifles.

But ersatz commandos are so Bush-era. These days, if you want in on the best federal grants, you're going to need a place on the virtual battlefield. Forget the National Guard; if you want to avoid the next draft, join the Ohio Cyber Security Council. Every government agency with a computer and copy of DOS for Dummies is singing "goodbye my sweetheart, hello cyber war." And in a sickening display of naked ambition by the military-industrial complex, defense contractors are buying up every cyber research firm on the market.
It's hard to take warnings of an "imminent" cyber-9/11 seriously, in part because no serious observer of electronic warfare considers it possible, let alone imminent. (Cylons rank higher on my list of imminent threats.) In his confirmation hearings, Secretary of State John Kerry actually called cyber security our "greatest threat" and a "21st century nuclear weapons equivalent." This is shameless, first-rate scare-mongering, the likes of which the world hasn't seen since — well, ever. At least nuclear weapons have the virtue of actually being able to do what we fear they can do. Detonate a minuscule one-megaton nuclear bomb in Times Square and then launch the most catastrophic cyber attack in human history against Los Angeles and see which one is worse. Infect the people of Dayton, Ohio, with smallpox and then have the nerve to suggest, "Well, at least it's not a direct-denial-of-service cyber attack!"

In 1951, General Walter Bedell Smith, the father of the modern Central Intelligence Agency, took measure of the Armed Forces Security Agency and decided to scrap the whole thing. Signals intelligence was too important to entrust to the "divided authorities and multiple responsibilities" of the branches of the armed forces. He wanted a "consistent, firmly administered security program," removed from the institutional stupidity of the Joint Chiefs of Staff, and persuaded Harry Truman to sign a memorandum creating the National Security Agency.

Today, the NSA is a massive, effective, well-run organization. And its establishment should have been the model for the nation's cyber security efforts. But instead of one centralized, effective body largely removed from the petty grievances and rivalries of government, the military-industrial complex created a many-headed hydra of cyber agencies, each of which pumps billions of dollars into Booz Allen, General Dynamics, and Lockheed Martin.
Here's how the nation's extraordinarily entangled cybersecurity organization looks:
The director of the National Security Agency, who is always a four-star general, reports directly to the undersecretary of defense for intelligence, and through the commander of U.S. Strategic Command, to the secretary of defense. The NSA director is also in charge of U.S. Cyber Command (CYBERCOM), and is responsible for protecting the federal government's computer networks from "cyber terrorism." CYBERCOM, meanwhile, is in charge of securing military computer networks and for planning cyber offensives on the battlefield — same leader, same job, and two different top-level-domains — dot-gov and dot-mil.

CYBERCOM itself splits into four service components. Yes: The Army, Navy, Air Force, and Marine Corps each need their own cyber warfare capability, in spite of a 40-year effort to bring joint capabilities to the battlefield. The U.S. Air Force 67th Network Warfare Wing, for example, is charged with "carrying out information operations to augment war fighting commands and national decision makers." That sounds an awful lot like Second Army's mission to "conduct cyberspace operations in support of full spectrum operations to ensure U.S. and allied freedom of action in cyberspace, and to deny the same to adversaries." It's not so different from the Marine Corps Forces Cyberspace Command, whose job it is to "conduct activities to direct the operations and defense of specified Department of Defense information networks and prepare to — and when directed — conduct full spectrum military cyberspace operations in order to enable actions in all domains, ensure U.S./Allied freedom of action in cyberspace and deny the same to our adversaries." What of the Navy's Fleet Cyber Command vision? You probably already know: To "conduct full-spectrum operations in and through cyberspace to ensure Navy and Joint/Coalition Freedom of Action while denying same to our adversaries."

Four branches, each with robust and almost-entirely overlapping missions, reporting to a command that belongs to the director of the National Security Agency, an agency that has largely the same mission on a different top-level-domain. This is alongside the Defense Information Systems Agency, which "provides, operates, and assures command and control, information sharing capabilities, and a globally accessible enterprise information infrastructure in direct support to joint warfighters, National level leaders, and other mission and coalition partners across the full spectrum of operations." (Even if you don't speak propeller-head, that's not too far from the defensive cyber missions listed above.)
Meanwhile, over at the hapless Department of Homeland Security, which has thus far been run by one feckless government functionary after another, there is the National Cyber Security Division (NCSD), whose mission is to maintain a cyberspace response system, and to devise and issue programs for the protection of critical infrastructure. The NCSD has under its charge a dozen divisions, programs, and offices that do various things that the NSA and CYBERCOM also do.

In many ways, this is but a fleeting glimpse of the government's cyber security missions from 30,000 feet. But it should be clear, at least in the abstract, that when you've got a hundred thousand people from a couple of dozen agencies, organizations, and offices, each with massively overlapping areas of responsibility, you're completely undermining the cyber-9/11 fear-mongering on which your expanded federal appropriations rest. In fact, you're practically begging for a cyber-9/11 — there's no way such a lumbering beast could ever react nimbly to a truly catastrophic attack. Which is why it's reassuring, on some level, that no such attacks exist even in theory.

A massive, ineffective apparatus to fight a threat that doesn't actually exist? This is the war our sorry government was elected to fight. I'm just looking forward to hearing what word Lee Greenwood rhymes with "cyber."


D.B. Grady is co-author of The Command: Deep Inside the President's Secret Army. He is a correspondent for The Atlantic, and lives in Baton Rouge, La. See more of his work at DBGrady.com.

Thursday, November 29, 2012

Evolving DDoS Attacks Force Defenders To Adapt


In the past, attackers using distributed denial-of-service (DDoS) attacks to take down Web sites or network servers typically adopted one of two tactics; flooding the site with a deluge of data or overwhelming an  application server with seemingly valid requests.

Yet increasingly, attackers are using a hybrid approach, using multiple vectors to attack. The attacks that hit financial firms in September and October, for example, often used a massive flood of data packets that would overwhelm a victim’s network connection, while a much smaller subset of traffic would target  vulnerable applications functions, consuming server resources.

The one-two punch is potent. Many financial firms thought they had the defenses in place to defeat such attacks but had problems staying accessible during the onslaught. Companies prepared to handle application-layer attacks or smaller volumetric attacks could not handle the 20Gbps or more that saturated their Internet connection. A recent report from network-security firm Prolexic found that the average attack bandwidth increased to nearly 5Gbps, with 20Gbps attacks quite common. In a year, the average volume of attacks had doubled, the firm found.

Read more: DDos Attacks More Potent These Days

Tuesday, September 25, 2012

White House said to plan executive order on cybersecurity

SAN FRANCISCO (Reuters) - The White House is preparing to direct federal agencies to develop voluntary cybersecurity guidelines for owners of power, water and other critical infrastructure facilities, according to people who said they had seen recent drafts of an executive order.

The prospective order would give the agencies 90 days to propose new regulations and create a new cybersecurity council at the Department of Homeland Security with representatives from the Defense Department, Justice Department, Director of National Intelligence and the Department of Commerce, a former government cyber-security official told Reuters.

"It tells those who have the ability to regulate to go forth and do so," said the person, who is currently outside the government and spoke on condition of anonymity in order to preserve access to government officials.

The draft executive order includes elements of what had been the leading cybersecurity overhaul bill in the Senate, which was defeated this summer amid opposition from industries opposed to increased regulation.

Senate Homeland Security Committee Chairman Joe Lieberman, an independent and one of the principal authors of that bill, on Monday urged the White House to issue such an order.
"The Department of Homeland Security has clear authority, if directed by you, to conduct risk assessments of critical infrastructure, identify those systems or assets that are most vulnerable to cyber attack and issue voluntary standards for those critical systems or assets to maintain adequate cybersecurity," Lieberman wrote to President Barack Obama.

The document has been circulating among the agencies and might go to top officials for their comments as soon as this week, another person involved in the process said.
A spokeswoman for the administration's National Security Council, Caitlin Hayden, confirmed that an order was being considered but would not provide details. "We're not commenting on the elements," Hayden said.

PUBLIC-PRIVATE COOPERATION

Former White House cybersecurity policy coordinator Howard Schmidt said the proposed order would also ask DHS to confer with independent agencies, such as electric regulators and others that don't answer to the president, to see who would take responsibility on cybersecurity.

The hope, said Schmidt, who has seen a recent draft, is that if those agencies won't let DHS act they would do it themselves, as the Securities and Exchange Commission did in October when it issued guidance on when companies should disclose cyber attacks.

The Commerce Department and the Pentagon declined to comment. Spokespeople for Lieberman and for Senator John Rockefeller, another Democratic leader on the issue who has asked for an executive order, said their offices had not been given copies of the draft.
Cybersecurity has become a major issue in Congress and for the White House, with intelligence officials warning of constant exploration of protected computer systems by hackers and both past incursions and the likelihood of more damaging future attacks on electric plants, banks and stock exchanges.

As of two weeks ago, the planned order did not include any penalties for companies that fail to adhere to the standards. or rewards for those who do. "There are no carrots or sticks," one person with a recent copy said.

If the order emerges before the election in November, it could become an issue in the campaign. Leading Republicans faulted the Lieberman bill as too onerous. The U.S. Chamber of Commerce, which also criticized that bill, declined to comment on Monday on the merits of a prospective order.

But Lieberman said his bill had been watered down in pursuit of a compromise and asked in his letter Monday that Obama explore means for making the standards mandatory.
Both Lieberman and administration officials have said they will still seek legislation, which could go further in many ways. It might, for example, provide liability protection for companies that share information with government officials or that meet the standards but still get hacked.

(Reporting by Joseph Menn in San Francisco; editing by Todd Eastham)

Monday, August 20, 2012

Former Hacker: Today’s Hacks Are All About the Money

Former Hacker: Today’s Hacks Are All About the Money Hackers have changed since the days of The Matrix. While most hackers used to hold iconoclastic ideals, with aspirations to “shock the system” for a perceived common good, today’s hacker/cracker community is more concerned with making a quick buck...........

Friday, July 27, 2012

Rise Is Seen in Cyberattacks Targeting U.S. Infrastructure

July 26, 2012

By DAVID E. SANGER and ERIC SCHMITT (New York Times

ASPEN, Colo. — The top American military official responsible for defending the United States against cyberattacks said Thursday that there had been a 17-fold increase in computer attacks on American infrastructure between 2009 and 2011, initiated by criminal gangs, hackers and other nations.

The assessment by Gen. Keith B. Alexander, who heads the National Security Agency and also the newly created United States Cyber Command, appears to be the government’s first official acknowledgment of the pace at which America’s electricity grids, water supplies, computer and cellphone networks and other infrastructure are coming under attack. Those attacks are considered potentially far more serious than computer espionage or financial crimes. 

General Alexander, who rarely speaks publicly, did not say how many attacks had occurred in that period. But he said that he thought the increase was unrelated to the release two years ago of a computer worm known as Stuxnet, which was aimed at taking down Iran’s uranium enrichment plant at Natanz. 

When the worm inadvertently became public, many United States officials and outside experts expressed concern that it could be reverse-engineered and used against American targets. General Alexander said he saw no evidence of that. 
General Alexander, as head of the N.S.A., was a crucial player in a covert American program called Olympic Games that targeted the Iranian program. But under questioning from Pete Williams of NBC News at a security conference here, he declined to say whether Stuxnet was American in origin; the Obama administration has never acknowledged using cyberweapons. 

General Alexander said that what concerned him about the increase in foreign cyberattacks on the United States was that a growing number were aimed at “critical infrastructure,” and that the United States remained unprepared to ward off a major attack. On a scale of 1 to 10, he said, American preparedness for a large-scale cyberattack is “around a 3.” He urged passage of legislation, which may come to a vote in the next week, that would give the government new powers to defend private computer networks in the United States. The legislation has prompted a struggle as American companies try to avoid costly regulation on their networks, and some civil liberties groups express concern about the effect on privacy. 

General Alexander said that the administration was still working out rules of engagement for responding to cyberattacks. Because an attack can take place in milliseconds, he said that some automatic defenses were necessary, as was the president’s involvement in any decisions about broader retaliation.

He confirmed that under existing authorities, only the president had the power to authorize an American-directed cyberattack. The first such attacks occurred under President George W. Bush. 

The Pentagon has said previously that if the United States retaliated for an attack on its soil, the response could come in the form of a countercyberattack, or a traditional military response. 

General Alexander spoke in a 75-minute interview at the Aspen Security Forum at the Aspen Institute here. The New York Times is a media sponsor of the four-day conference. Another conference speaker, Matthew Olsen, the director of the National Counterterrorism Center, addressed the escalating “hot war” between Israel and Iran and Iranian-backed groups like Hezbollah.

Iran has blamed Israel for assassinations of several of its nuclear scientists. Israel has accused Hezbollah operatives backed by Iran of carrying out the suicide bombing last week that killed five Israeli tourists and a local bus driver in Bulgaria. 

The United States has said Iran was behind a thwarted plot last fall to kill Saudi Arabia’s ambassador to the United States. 

“Both with respect to Iran and Hezbollah, we’re seeing a general uptick in the level of activity around the world in a number of places,” Mr. Olsen said.

Mr. Olsen did not address the Bulgaria attack, but he said the plot to kill the Saudi envoy in Washington “demonstrated that Iran absolutely had the intent to carry out a terrorist attack inside the United States.” MORE IN U.S. (12 OF 27 ARTICLES) Quiet Duo Forged Road Deal for U.S. and Pakistan Read More »

Wednesday, June 13, 2012

Wednesday, May 30, 2012

BTOD (Bring Your Own Device) Whitepaper

Good whitepaper: BYOD (Bring Your Own Device). See how companies are coping with the influx of these devices in the workplace. Click here.